Executive brief
A security flaw exists in the a4m4 Student Management System, a platform used to manage student records and administrative tasks. Due to a coding error, the system fails to properly block unauthorized users from accessing administrative pages. An attacker can bypass the login screen to view, modify, or delete sensitive student data, potentially leading to a full compromise of the school's records.
Technical details
The a4m4 Student-Management-System (up to commit f0c5f684) contains an Execution After Redirect (EAR) vulnerability within the admin/ directory, specifically affecting files like addstudent.php and updatestudent.php. The root cause is an improper access control implementation where the code issues a 'Location' redirect header via PHP's header() function when a session is invalid, but fails to terminate script execution with exit() or die(). Consequently, the server continues to process and transmit the protected HTML content and administrative forms to the client. A remote, unauthenticated attacker can exploit this by ignoring the 302 redirect to gain full access to administrative functions and sensitive student data. As of the advisory date, the vendor has not responded to the issue report.
Affected products
- a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0
Timeline
- 2026-05-11: disclosed: Issue reported on GitHub repository
- 2026-06-01: advisory: NVD/VulDB advisory published